Race condition in ClamAV - #VU141304
Published: August 7, 2026
Vulnerability details
The vulnerability allows a local user to replace source paths during quarantine move and remove actions.
The vulnerability exists due to race condition in FreeBSD quarantine move and remove actions when handling source paths. A local user can manipulate source paths to replace them during quarantine move and remove actions.
This issue applies on FreeBSD.